[GHSA-h524-452v-82p9] Decoding a maliciously-crafted MIME header containing... - #7909
tarampampam wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Pull request overview
Note
Copilot was unable to run its full agentic suite in this review.
Updates the GHSA advisory metadata by adding a summary and populating the affected package/range information.
Changes:
- Updated the advisory
modifiedtimestamp - Added a
summaryfield - Filled in the
affectedsection with Go ecosystem package/range and last-known affected range metadata
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| "aliases": [ | ||
| "CVE-2026-42504" | ||
| ], | ||
| "summary": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU. Updated 3 days", |
| "aliases": [ | ||
| "CVE-2026-42504" | ||
| ], | ||
| "summary": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU. Updated 3 days", |
There was a problem hiding this comment.
| "summary": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU. Updated 3 days", | |
| "summary": "Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU", |
|
👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the |
|
Up |
|
👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the |
|
👋 Hi @tarampampam, unfortunately we can't accept this PR because the GitHub Advisory Database doesn't support advisories for issues in the Go standard library, only packages on pkg.go.dev. Thanks for your interest in GHSA-h524-452v-82p9 and the Go ecosystem! |
Updates
Comments
Affected versions and package name updated